Built-in Policy

Chute's built-in policies are DIRECT, REJECT with its variants, and PROXY. DIRECT sends the request to the host directly. REJECT refuses it; the variants below refuse it in different ways.

In addition, when a [Tailscale] section is configured, the built-in identifier TAILSCALE becomes available. See Tailscale Configuration for details.

All of them can be used in rules and policy groups directly. You can also define an alias in the proxy section.

REJECT Variants

Policy Behavior
REJECT Refuses the connection. A request through the HTTP proxy gets a refusal response, or the error page when show-error-page-for-reject is on.
REJECT-NO-DROP Same as REJECT, and never escalated to REJECT-DROP (see below).
REJECT-DROP Never answers: the connection is held silently until it times out, and UDP is dropped.
REJECT-TINYGIF, REJECT-IMG Answers 200 with a 1×1 GIF.
REJECT-DICT Answers 200 with an empty JSON object {}.
REJECT-ARRAY Answers 200 with an empty JSON array [].
REJECT-200 Answers 200 with an empty body.
REJECT-VIDEO Answers 200 with a blank MP4.

The 200 answers need a plain HTTP/1 request — plain HTTP, or HTTPS decrypted by MitM. When none arrives within 3 seconds, the connection is closed as with REJECT. Except for REJECT-DROP, rejected UDP is answered with an ICMP port unreachable.

Answers Chute generates itself — Map Local, a script's response, and the answers and error page of URL Rewrite and the REJECT policies — follow HTTP: the answer to a HEAD request is the header alone, with the Content-Length a GET would get, and an answer with status 204, 205 or 304 carries neither a body nor a Content-Length.

Like Surge, a host refused by REJECT, REJECT-TINYGIF or REJECT-IMG more than 50 times within 30 seconds is handled as REJECT-DROP for the next 30 seconds, so a client retrying in a tight loop stops getting instant answers. REJECT-NO-DROP and the other variants are never escalated.

PROXY

For compatibility with Shadowrocket, PROXY can be used in rules and policy groups without being defined. It stands for the policy selected for Global mode — the one you pick from the global policy list — and follows that choice as it changes. If the configuration defines its own policy or group named Proxy (in any letter case), that definition is used instead. When nothing can be selected, the configuration still loads with a notice, and connections that reach PROXY are refused.

Alias

[Proxy]
On = direct
Off = reject

Then you can use 'On' and 'Off' as a policy name in rule and policy group. Any other parameter on such a line is ignored, with a notice in the log.

S. Smart Rabbit LLC © All Rights Reserved            updated 2026-09-25 00:02:29

results matching ""

    No results matching ""